Hybrid IT Control Approaches. Integrating ISO 27001, COBIT, and NIST for Enhanced Information Security

Authors

DOI:

https://doi.org/10.56880/experior52.3

Keywords:

IT controls, Information security, ISO 27001, COBIT, hybrid approach

Abstract

This study designs a hybrid approach to IT controls, integrating the international standards ISO/IEC 27001, COBIT 2019, and NIST CSF to strengthen information security in organizations. A projective and descriptive research approach was used, employing a qualitative methodology based on documentary and comparative analysis of the three regulatory frameworks. The process was structured according to an individual and comparative analysis of their structures and strengths, the identification of points of convergence and complementarity, and a projective synthesis to design the model. The analysis revealed the unique and complementary value of each framework: ISO/IEC 27001 (systemic management), COBIT 2019 (governance and alignment), and NIST CSF (tactical operation and resilience). The study's contribution is the proposal of the Hybrid Cyber Resilience Model, a three-dimensional architecture that connects the three layers in a constantly self-reinforcing cycle, ensuring comprehensive security coverage aligned with the needs of each organization. It is concluded that the hybrid integration of the three frameworks provides better coverage than their isolated application, improving risk management, resource utilization, and strengthening response and recovery capabilities. This is presented as a projective theoretical proposal that, as a second step, requires empirical validation, which is proposed as a line of research.

Downloads

Download data is not yet available.

References

Adams, N-R. (2024). COBIT 2019: IT governance framework. https://itlawco.com/cobit-2019-it-governance-framework/#:~:text=de%20la%20organizaci%C3%B3n.-,Creaci%C3%B3n%20de%20valor,como%20personas%2C%20procesos%20y%20tecnolog%C3%ADa.

Alcaraz, C., & Zeadally, S. (2015). Critical infrastructure protection: Requirements and challenges for the 21st century. International journal of critical infrastructure protection, 8, 53-66. https://doi.org/10.1016/j.ijcip.2014.12.002

Anoruo, C., CISM, CGEIT & CRISC. (2019). Employing COBIT 2019 for Enterprise Governance Strategy. ISACA. https://www.isaca.org/resources/news-and-trends/industry-news/2019/employing-cobit-2019-for-enterprise-governance-strategy#:~:text=Objetivos%20de%20gobernanza%20y%20gesti%C3%B3n,de%20los%20objetivos%20que%20contienen:&text=Evaluar%2C%20dirigir%20y%20supervisar%20(EDM,%2C%20evaluar%20y%20valorar%20(MEA)

Arévalo Ascanio, J. G., Bayona Trillos, R. A., & Rico Bautista, D. W. (2015). Implantación de un sistema de gestión de seguridad de información bajo la ISO 27001: análisis del riesgo de la información. Tecnura, 19(46), 123-134. http://dx.doi.org/10.14483/udistrital.jour.tecnura.2015.4.a10

Batte, B. (2025). ISO 27001 and Alternative Frameworks for Managing Information Security Risks. Available at SSRN 5546398. https://dx.doi.org/10.2139/ssrn.5546398

Bernete, F. (2013). Análisis de contenido. Conocer lo social: estrategias y técnicas de construcción y análisis de datos, 193-203. https://docta.ucm.es/rest/api/core/bitstreams/d7587d54-592d-416c-81b0-15685c3f3204/content

Boné-Andrade, M. F., Pinargote-Bravo, V. J., & Bonilla-Fierro, L. F. (2023). Estrategias de ciberseguridad en entornos de trabajo híbridos y remoto. Revista Científica Ciencia y Método, 1(4), 31-43. https://doi.org/10.55813/gaea/rcym/v1/n4/21

Clomera, A. (2025). Exploring the NIST CSF Categories and Subcategories: A Comprehensive Overview. https://ipkeys.com/blog/nist-csf-categories/

Cristaldo, P. R., Ballejos, L. C., & Ale, M. A. (2019). Propuesta metodológica de enfoque “híbrido” para la gestión de proyectos de tics en la administración pública: Implementación y verificación. Revista Tecnología y Ciencia, (34), 16-36. https://doi.org/10.33414/rtyc.34.16-36.2019

Cruz García, M. A. (2019). Fuentes de información. Boletín científico de las ciencias económico administrativas del ICEA, 8(15), 57-58. https://doi.org/10.29057/icea.v8i15.4864

Everett, C. (2011). Is ISO 27001 worth it? Computer Fraud & Security, 2011(1), 5-7. https://doi.org/10.1016/S1361-3723(11)70005-7

Fathurohman, A., & Witjaksono, R. W. (2020). Analysis and design of information security management system based on ISO 27001: 2013 using Annex Control (Case Study: District of Government of Bandung City). Bulletin of Computer Science and Electrical Engineering, 1(1), 1-11. https://doi.org/10.25008/bcsee.v1i1.2

Harizaj, M., Qafa, R., & Idrizi, O. (2025). Strategic Vulnerability Analysis of Cybersecurity Frameworks: Toward a Hybrid Model for Governance and Resilience. In International Conference on Intelligence-Based Transformations of Technology and Business Trends (pp. 84-96). Cham: Springer Nature Switzerland. https://doi.org/10.1007/978-3-032-07370-9_8

ISO. (2018). ISO/IEC 27000:2018. Tecnología de la información — Técnicas de seguridad — Sistemas de gestión de la seguridad de la información — Descripción general y vocabulario. ISO/IEC. https://www.iso.org/standard/73906.html

Lainhart, J., Conboy, M., & Saull, R. (2018). COBIT 2019 Governance and Management Objectives. Schaumburg: ISACA. https://netmarket.oss.aliyuncs.com/df5c71cb-f91a-4bf8-85a6-991e1c2c0a3e.pdf

León-Acurio, J. V., Mora-Aristega, J. E., Huilcapi-Masacon, M. R., Tamayo-Herrera, A. del P. & Armijos-Maya, C. A. (2018). COBIT como modelo para auditorías y control de los sistemas de información. Polo del Conocimiento: Revista científico-profesional, 3(4), 17-36. https://dialnet.unirioja.es/servlet/articulo?codigo=9573039

Metin, B., Sevim, S. B., & Wynn, M. (2025). Cybersecurity Strategy Development: Towards an Integrated Approach Based on COBIT and ISO 27000 Series Standards. Standards, 5(4), 33. https://doi.org/10.3390/standards5040033

NIST. (2018). Marco para la mejora de la seguridad cibernética eninfraestructuras críticas. Instituto Nacional de Estándares y Tecnología. https://www.nist.gov/system/files/documents/2018/12/10/frameworkesmellrev_20181102mn_clean.pdf

Pascoe, C. E. (2023). Public draft: The NIST cybersecurity framework 2.0. National Institute of Standards and Technology. https://www.authonet.com/assets/National-Institute-of-Standards-and-Technology.(NIST).Cybersecurity-Framework.CSWP.29.ipd.pdf

Rochmadi, T., Fadlil, A., & Riadi, I. (2025). Developing a Delphi Validated Instrument for Assessing Digital Forensics Readiness Based on COBIT 2019. International Journal of Advances in Data and Information Systems, 6(3), 749-762. https://doi.org/10.59395/ijadis.v6i3.1453

Salihu, A., & Dervishi, R. (2024). Evaluating the Impact of Risk Management Frameworks on IT Audits: A Comparative Analysis of COSO, COBIT, ISO/IEC 27001, and NIST CSF. In 2024 International Conference on Electrical, Communication and Computer Engineering (ICECCE) (pp. 1-8). IEEE. https://doi.org/10.1109/ICECCE63537.2024.10823548

Shojaie, B., Federrath, H., & Saberi, I. (2014). Evaluating the effectiveness of ISO 27001: 2013 based on Annex A. In 2014 Ninth International Conference on Availability, Reliability and Security (259-264). IEEE. https://doi.org/10.1109/ARES.2014.41

Sulistyowati, D., Handayani, F., & Suryanto, Y. (2020). Comparative analysis and design of cybersecurity maturity assessment methodology using nist csf, cobit, iso/iec 27002 and pci dss. JOIV: International Journal on Informatics Visualization, 4(4), 225-230. https://dx.doi.org/10.30630/joiv.4.4.482

Downloads

Published

2026-07-15

How to Cite

Lin Ríos , I. K., Bruce , C. V., & Gonzalez Vega , A. (2026). Hybrid IT Control Approaches. Integrating ISO 27001, COBIT, and NIST for Enhanced Information Security. Experior, 5(2), 136-148. https://doi.org/10.56880/experior52.3